{
  "slug": "cyber-insurance-premium-vs-retention",
  "title": "Cyber Insurance Premium vs. Retention Calculator",
  "heading": "Cyber Insurance Premium vs. Retention Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/cyber-insurance-premium-vs-retention",
  "summary": "Compare a higher deductible/lower premium against expected annual loss.",
  "description": "Cyber insurance policies trade premium against retention (deductible): a higher retention lowers your annual premium but means you self-fund more of any incident before coverage kicks in. This calculator compares two policy options by combining the premium cost with expected out-of-pocket cost based on your own incident frequency assumption, so you can see total expected annual cost rather than just sticker premium price. It also flags a common trap: choosing the cheapest premium without checking whether your realistic annual incident frequency and severity would blow through the retention on a regular basis, turning a 'discount' into a bad bet. This isn't a substitute for reading policy sub-limits and exclusions (war exclusion, unencrypted-device exclusion, and 'failure to maintain minimum security standards' clauses have all been used to deny real claims), but it does make the pure cost tradeoff explicit.",
  "formula": "Expected annual cost = premium + (expected incidents/year × average incident cost capped at retention amount per incident, or full cost above retention up to policy limit).",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=cyber-insurance-premium-vs-retention",
  "inputs": [
    {
      "id": "premiumOptionA",
      "label": "Option A: annual premium (lower retention)",
      "kind": "number",
      "hint": null,
      "default": 45000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "retentionA",
      "label": "Option A: retention (deductible) per incident",
      "kind": "number",
      "hint": null,
      "default": 25000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "premiumOptionB",
      "label": "Option B: annual premium (higher retention)",
      "kind": "number",
      "hint": null,
      "default": 30000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "retentionB",
      "label": "Option B: retention (deductible) per incident",
      "kind": "number",
      "hint": null,
      "default": 100000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "expectedIncidents",
      "label": "Expected covered incidents per year",
      "kind": "number",
      "hint": null,
      "default": 0.4,
      "unit": null,
      "min": 0,
      "max": 10
    },
    {
      "id": "avgIncidentCost",
      "label": "Average incident cost (before insurance)",
      "kind": "number",
      "hint": null,
      "default": 400000,
      "unit": null,
      "min": 0,
      "max": null
    }
  ],
  "outputs": [
    {
      "id": "expectedCostA",
      "label": "Option A total expected annual cost",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "expectedCostB",
      "label": "Option B total expected annual cost",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "difference",
      "label": "Difference (A − B)",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "cheaperOption",
      "label": "Lower expected-cost option",
      "format": "raw",
      "hint": null,
      "primary": false
    },
    {
      "id": "outOfPocketB",
      "label": "Out-of-pocket per incident under Option B",
      "format": "currency",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Option A: annual premium (lower retention): 45000",
      "Option A: retention (deductible) per incident: 25000",
      "Option B: annual premium (higher retention): 30000",
      "Option B: retention (deductible) per incident: 100000",
      "Expected covered incidents per year: 0.4",
      "Average incident cost (before insurance): 400000"
    ],
    "outputs": [
      "Option A total expected annual cost: $55,000",
      "Option B total expected annual cost: $70,000",
      "Difference (A − B): -$15,000",
      "Lower expected-cost option: Option A (lower retention) is cheaper on expected value",
      "Out-of-pocket per incident under Option B: $100,000"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter option a: annual premium (lower retention).",
      "Enter option a: retention (deductible) per incident.",
      "Enter option b: annual premium (higher retention).",
      "Enter option b: retention (deductible) per incident.",
      "Enter expected covered incidents per year.",
      "Enter average incident cost (before insurance).",
      "Read your option b total expected annual cost on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "premiumOptionA": 27000,
        "retentionA": 15000,
        "premiumOptionB": 18000,
        "retentionB": 60000,
        "expectedIncidents": 0.24,
        "avgIncidentCost": 240000
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "premiumOptionA": 45000,
        "retentionA": 25000,
        "premiumOptionB": 30000,
        "retentionB": 100000,
        "expectedIncidents": 0.4,
        "avgIncidentCost": 400000
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "premiumOptionA": 72000,
        "retentionA": 40000,
        "premiumOptionB": 48000,
        "retentionB": 160000,
        "expectedIncidents": 0.6400000000000001,
        "avgIncidentCost": 640000
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Should I always pick the lower expected-cost option?",
      "a": "Not automatically. Expected value math favors higher retention when incident frequency is low, but it assumes you can actually absorb the full retention amount in cash without disrupting operations if an incident hits in a bad year; if a $100,000 retention would strain your reserves, the lower-retention option's cash-flow predictability has real value beyond the math."
    },
    {
      "q": "What incident frequency should I assume?",
      "a": "Use your own claims/incident history if you have 3+ years of data; otherwise, industry cyber incident frequency benchmarks from your broker (often available by industry and revenue band) are more reliable than a guess. Small and mid-size companies commonly underestimate this because near-misses caught by existing controls never show up as 'incidents' in memory."
    },
    {
      "q": "Does this account for sub-limits within the policy?",
      "a": "No, this compares premium and retention only. Real policies often have separate sub-limits for ransomware, business interruption, and regulatory fines that can be far lower than the headline policy limit, so always cross-check the actual policy schedule against your largest realistic loss scenario."
    },
    {
      "q": "Why would an insurer deny a claim even with a valid policy?",
      "a": "Common real-world denial reasons include failure to maintain the minimum security controls attested to in the application (like MFA that was promised but not actually enforced everywhere), war/nation-state exclusions invoked for certain ransomware groups, and claims filed outside the notification window specified in the policy."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy",
    "https://www.revenuelab.fyi/toolbox/breach-cost-per-record",
    "https://www.revenuelab.fyi/toolbox/incident-response-retainer-value"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Cyber Insurance Premium vs. Retention Calculator (https://www.revenuelab.fyi/toolbox/cyber-insurance-premium-vs-retention)"
}